NextFin News - Europe is no longer debating whether Russia is waging hybrid war against it; it is building new institutions to fight one. In the 48 hours before a mid-September address to the European Parliament, a Russian warship fired flares at a Danish helicopter, NATO jets shot down a drone over Lithuania, Russia struck a passenger train near Ukraine's border, and Poland pulled a drone from its waters. The response now under discussion is a standing EU mechanism for incidents that fall below the threshold of armed attack - Europe's own version of NATO's Article 4 - and it marks an admission that the old playbook has run out.
The central question is not whether Moscow is escalating. It is whether Europe's answer arrives fast enough to matter. The escalation is structural, not cyclical: the gray zone itself has become the battlefield, and Moscow's strategy is to impose sustained cost without ever triggering collective defence. That is why the proposed Emergency Security Protocol matters more than any single retaliatory measure - and why its success hinges on one bottleneck that Europe has historically struggled with: attribution speed.
Data as of September 26, 2026. All figures sourced from EU institutions, NATO member governments, the U.S. Congressional Research Service, and threat-intelligence tracking.
The Situation: A Campaign That No Longer Hides
Since Russia's full-scale invasion of Ukraine began in 2022, hybrid attacks against Europe have risen steadily, according to Kaja Kallas, the EU's High Representative for Foreign Affairs. But the character of the campaign changed across 2025 and 2026. Suspected violations of NATO airspace by what are assessed to be Russian drones or jets reached unprecedented levels: a threat-intelligence tracker recorded 30 such violations between September 2025 and January 2026, compared with 23 suspected or confirmed violations across the entire period from March 2022 to August 2025. The most frequently targeted countries have been Poland and Romania, though incidents have reached Germany, the UK, Denmark, and Norway.
The numbers tell a story of tempo, not just volume. NATO air-policing and national defusal teams scrambled across Romania, Bulgaria, Latvia, and neutral Moldova in more than 80 drone-related events in 2026 alone, according to conflict-data tracking. On September 1, 2026, Estonian defence forces tracked multiple Russian drones near the border, including one that breached southeastern Estonian airspace; NATO F-16s stationed at the Ämari Air Base were scrambled. Three weeks later, on September 24, Romanian authorities said an aerial asset entered its airspace for about four minutes before falling near Solca in Suceava County, close to the Ukrainian border; schools in four towns were suspended and no casualties were reported. Drone overflights, crashes, and explosions have become almost daily occurrences in parts of Eastern Europe.
The physical sabotage track runs parallel to the airspace campaign. On the night of August 4-5, 2026, an explosive quadcopter struck near the fuel tank of an Antonov An-124 cargo aircraft at Leipzig/Halle Airport in Germany, and a second drone carrying explosives was discovered on the airfield - a major logistics hub for Ukrainian and NATO supplies. On September 1, the German government formally accused Russia of responsibility. Interior Minister Alexander Dobrindt said police investigations, patterns of offences, and intelligence findings together established Russian responsibility. Berlin raised its national threat level from "general" to "high," ordered the closure of the Russian consulate in Bonn and the Russian House cultural centre in Berlin, and tightened entry controls for Russian nationals.
"We are not at war, but we are a daily target of hybrid attacks," Dobrindt told reporters. "That a drone armed with explosives is at an airport is a new threat scenario."
A week later, a building used by Milrem Robotics, the Estonian maker of unmanned ground vehicles deployed in Ukraine, was damaged by fire. Prime Minister Kristen Michal said one line of investigation was a possible act of sabotage with Russian involvement; three Latvian suspects were later extradited to Estonia and remanded as investigators examined all possibilities, including sabotage. In the Black Sea on August 20, Romanian authorities intercepted and destroyed an explosive-laden Russian surface maritime drone detected near the Neptun Deep offshore gas project, an incident assessed as an attempt to threaten energy infrastructure and test NATO maritime response protocols.
The pattern is deliberate: each incident is calibrated to stay below the line that would compel a military response, while collectively eroding the sense of security on NATO soil. As Dutch Defence Minister Ruben Brekelmans warned in early 2026, "There is a gray area, and as Russia is taking additional steps, the gray zone is becoming darker."
Why This Is Structural, Not Cyclical
The first-order read of these events is familiar: Russia lashes out when it struggles on the battlefield. Finnish Defence Minister Antti Häkkänen put it plainly at an EU defence ministers' meeting: Russia is "not gaining any success on the battlefield. So that's why they are increasing pressure and hybrid actions towards [countries] supporting countries for Ukraine." That framing is correct as far as it goes - but it mistakes the proximate cause for the mechanism.
A cyclical campaign would ebb when the battlefield situation changes. This one will not, because it is built on a structural feature of the European security architecture: the gap between nuisance and war. Article 5 of the North Atlantic Treaty obliges allies to respond to an armed attack. Article 4 allows consultations when territorial integrity or security is threatened. Between those two articles lies a vast space where drones can breach airspace, cables can be severed, and arson can damage defence-industrial sites without ever forcing a collective decision. Russian military doctrine has a name for exploiting that space. In a 2013 article, General Valeriy Gerasimov, Chief of the General Staff, wrote that "the very rules of war have changed. The role of nonmilitary means of achieving political and strategic goals has grown and, in many cases, they have exceeded the power of force of weapons in their effectiveness." The strategy that grew from that insight - New Generation Warfare - treats ambiguity as a weapon.
The evidence that this is a regime shift rather than a temporary wave is threefold. First, the target set has widened beyond the former Soviet sphere: influence operations, airspace violations, and sabotage now reach Germany, the UK, Denmark, Norway, and the Baltic seabed. Second, the tempo has institutionalized - more than 80 drone-related events in nine months is not a spike; it is a sustained operating rhythm that forces defenders to spend continuously while attackers choose the time and place. Third, the toolkit is integrated rather than opportunistic: U.S. congressional analysts document a campaign combining cyberattacks on government systems, systematic GPS jamming, undersea-cable disruption, drone incursions, arson against defence contractors, and information operations. The Polish Institute of International Affairs has described the same convergence in the Baltic region, where sabotage of physical infrastructure, jamming, cyber operations, and influence campaigns form a single campaign architecture.
The counter-thesis deserves weight. Skeptics - including some Western intelligence officials and European diplomats - argue that much of the activity is opportunistic probing rather than a coordinated strategic shift, that a significant share of incidents could be accidental or the work of non-state actors, and that Moscow retains an interest in avoiding a direct NATO confrontation. Under this view, the appropriate response is improved resilience and case-by-case attribution, not new treaty-level machinery that could escalate a drone incident into a political crisis. There is also the risk of attribution error: acting on weak evidence, as one Estonian defence official cautioned, can hand Moscow a propaganda victory and fracture the very unity the response is meant to demonstrate.
That caution is legitimate but incomplete. It treats each incident as independent, when the strategic effect lies in their accumulation. Even if individual cases remain ambiguous, the aggregate pattern - the frequency, the geography, the target selection - is the signal. And the cost of inaction compounds: every unattributed incident teaches Moscow that the gray zone is free. The structural call stands: this is a durable campaign designed to normalize insecurity inside NATO borders, and it will persist regardless of battlefield swings in Ukraine because its objective is not territorial gain in Europe - it is the erosion of European political will.
The mechanism, in one sentence: Moscow trades deniability for duration, accepting low-intensity, attributable-enough attacks that never force a collective response, in order to exhaust European attention and unity over years rather than win anything in days.
The Second-Order Problem: Attribution Is the New Deterrent
The conventional wisdom is that deterrence requires capability - more air defences, more patrols, more sanctions. Those matter. But the second-order constraint is time. In the gray zone, the side that attributes fastest wins the political battle, because the window between an incident and the public's demand for an answer is measured in hours, while traditional intelligence attribution is measured in weeks.
Germany's handling of the Leipzig attack shows the model. Berlin did not merely retaliate; it published its case. Kallas singled out "Germany's investigation, attribution and clear public communication following the Leipzig attack" as important precisely because attribution strips Russia of its primary weapon: ambiguity.
"Russia has always used ambiguity as a weapon," Kallas said. "If we attribute the attacks, Russia cannot hide and our citizens can see the patterns and understand the playbook too."
That is the transmission channel: public attribution converts a deniable nuisance into a documented act of statecraft, which then legitimizes proportionate countermeasures - sanctions, expulsions, visa restrictions - that would otherwise look like escalation.
This is why the proposed Emergency Security Protocol is the most consequential institutional development in the story. European Commission President Ursula von der Leyen, in her State of the Union address in Strasbourg on September 16, 2026, framed it explicitly: "We urgently need a consensus on how to respond to certain incidents. Those which fall below armed aggression but clearly threaten our national security... It is time for Europe's own Article 4 - or an Emergency Security Protocol." The mechanism, as described by Kallas, would apply to "everything that is under the threshold of armed aggression" and could trigger coordinated responses including further sanctions and restrictions on visas for Russian tourists - always, officials stress, in close cooperation with NATO.
The design logic is sound: create a standing consultation and response track for sub-Article-5 incidents so that Europe no longer has to invent one after each attack. But the protocol's deterrent value depends entirely on the speed and credibility of the attribution that feeds it. A mechanism that convenes three weeks after an incident, once the news cycle has moved on, is a bureaucratic exercise, not a deterrent. This is the gap between the policy announcement and the operational reality: Europe has the political tools; it lacks the intelligence-fusion tempo to use them while they still matter.
The EU has been building the pieces. A hybrid sanctions regime created in October 2024 targets those who undermine democracies, sabotage critical infrastructure, conduct foreign information manipulation and interference, or instrumentalize migration. As of July 2026, the EU had sanctioned 26 entities and more than 100 individuals for supporting Russia's destabilizing activities, including cyberattacks; in July it added nine individuals and four entities over cyber aggression; in mid-September it sanctioned twelve individuals and two entities over information manipulation and cyber attacks; and on September 24 it listed a further individual over information-manipulation activities. Kallas also noted that EU sanctions have "already deprived the Russian economy of one trillion euro," and that naval operations are boarding suspected shadow-fleet vessels, with hundreds of ships de-flagged as fewer countries allow them to sail under their flags.
These are real costs. But they are retrospective - imposed after the fact, on actors already identified. The forward-looking question is whether Europe can move from punishing the last attack to preventing the next one. That requires something harder: shared intelligence, common attribution standards, and the political willingness to act on evidence that is strong enough to be defensible but assembled fast enough to be relevant.
The Response Landscape: What Europe Is Actually Building
The institutional response has three layers, and each reveals a different constraint.
Layer one is NATO's military adaptation. Operation Eastern Sentry, launched on September 12, 2025 with no end date, is the Alliance's response to Poland's Article 4 declaration after 19 to 23 unarmed Russian drones violated Polish airspace on September 9-10, 2025; up to four were shot down, most by Dutch F-35s. Supreme Allied Commander Europe General Alexus G. Grynkewich described it as "even more focused and flexible deterrence and defence, wherever and whenever necessary to protect our population and deter further reckless and dangerous acts." The operation stretches from the Baltic to the Black Sea and represents a genuine shift from symbolic air policing to a standing, multi-domain presence. Its limitation is jurisdictional: NATO can defend airspace, but it cannot sanction, prosecute, or expel diplomats. The hybrid campaign deliberately exploits precisely those non-military domains.
Layer two is the EU's political and economic toolkit. Beyond sanctions, Brussels has cut Russia's diplomatic presence in the EU, introduced new requirements for intra-Schengen travel, and capped the Russian mission to the EU at 40 staff. Member states are acting in parallel - Hungary expelled 10 Russian diplomats. Kallas has also floated banning visas for Russia's ex-combatants and reviewing tourist visas to "reduce the pool of people conducting attacks on European soil." These measures raise the cost of operating inside Europe, but they are blunt instruments that take months to negotiate and can be absorbed by a state that has already been largely severed from Western financial and travel systems.
Layer three is the proposed European Security Council. Von der Leyen also called for a new security council involving Canada, Norway, the United Kingdom, and Ukraine - non-EU states that are central to European defence but outside its institutions. This is an acknowledgment that the EU's security perimeter no longer matches its membership map. The constraint here is sovereignty: a council that includes non-members can coordinate, but it cannot command, and it cannot substitute for the decision-making speed that hybrid attacks demand.
Taken together, the architecture is more coherent than anything Europe had in 2022. But coherence is not the same as speed, and speed is the variable Moscow is testing.
What Comes Next: Scenarios and Signals
The forward picture splits by time horizon, and the horizons point in different directions.
In the short term - the next three to six months - expect continued high-frequency probing. Winter historically brings a surge in cyber operations against energy infrastructure, and the drone campaign shows no sign of pausing. The most likely flashpoints remain Poland, Romania, the Baltic states, and Moldova, with the Black Sea and Baltic seabed as maritime risk corridors. Markets and governments should price in recurring disruption: airport closures, flight diversions, localized energy outages, and episodic spikes in defence and cyber-security spending.
In the medium term - six to eighteen months - the test is whether the Emergency Security Protocol moves from proposal to functioning machinery. If it does, Europe gains a credible escalation ladder between silence and Article 5, and the cost of each gray-zone incident rises. If it stalls in negotiation - as EU security initiatives often do - Moscow receives confirmation that the gray zone remains free, and the campaign's tempo will ratchet higher. The decisive variable is not political will in the abstract; it is whether member states agree to share intelligence fast enough to make attribution a collective asset rather than a national secret.
In the long term, the structural call implies a durable elevation of Europe's security baseline. Defence budgets will not revert to pre-2022 levels; critical infrastructure will be hardened as a permanent line item; and the political consensus that underpins support for Ukraine will be tested not by battlefield news alone but by the accumulation of attacks on European soil. The campaign's ultimate objective is not a single concession but the slow erosion of that consensus - which means Europe's success is measured in resilience, not victories.
Three signals would falsify the structural-escalation thesis. First, if Russia-attributed incidents inside NATO and EU territory fall materially over the next two quarters - drone-related scrambles returning toward pre-September-2025 levels - that would suggest the campaign was coercive bargaining rather than a regime shift. Second, if Moscow publicly accepts a verified incident-prevention channel with the EU or NATO for airspace and maritime safety, the escalation dynamic would be reversible. Third, if the Emergency Security Protocol is adopted but remains unused for twelve months because members cannot agree on attribution, the mechanism is cosmetic and the structural gap persists unchanged. The single most important metric to watch is the interval between incident and joint attribution: if it stays in weeks, the campaign continues to win; if it compresses to days, deterrence begins to bite.
The base case is continued escalation at current or higher tempo, with the protocol adopted in some form but hobbled by attribution delays. The upside case is that public attribution - following the Leipzig model - becomes routine, raising the political cost per incident enough to slow the campaign. The downside case is a successful attack on critical infrastructure that causes mass casualties or prolonged outages, forcing Europe to choose between a response it cannot sustain and a humiliation it cannot absorb.
Russia's hybrid campaign against Europe is not a prelude to war; it is a form of war already in progress, conducted in the space that treaties left empty. Europe's answer - a protocol for the gray zone - is the right institutional innovation, but institutions do not deter by existing. They deter by acting faster than the adversary can deny. Until attribution moves at the speed of the attack, the gray zone will remain the one domain where Moscow sets the rules, the tempo, and the price of admission.
Explore more exclusive insights at nextfin.ai.
